General

  • Target

    24568f521777a9ce638b44bee8bd6d56_JaffaCakes118

  • Size

    213KB

  • Sample

    240704-c11ahazdqn

  • MD5

    24568f521777a9ce638b44bee8bd6d56

  • SHA1

    be66c7ebbfa4d705da7a41dd8ff8289fdf12fd65

  • SHA256

    097d919fb061ccde8a8c725c626ce87282e5049789cd05b1d413ba936e322bed

  • SHA512

    c6c44f2f323f379486c3d7b27e0b6e6f766c7a152cd1ca15c702e58a953cb8cddf8a573cf2b9d972087143531d569130e867dbed6738293f38c2692d189151dd

  • SSDEEP

    3072:sr85CDVP6CIqmpRvFLifSC1EKyAqiv/sZpMmZMCNZDgKlGD7rmk:k90RpRvFLiEtTZqmZZNpngXmk

Malware Config

Targets

    • Target

      24568f521777a9ce638b44bee8bd6d56_JaffaCakes118

    • Size

      213KB

    • MD5

      24568f521777a9ce638b44bee8bd6d56

    • SHA1

      be66c7ebbfa4d705da7a41dd8ff8289fdf12fd65

    • SHA256

      097d919fb061ccde8a8c725c626ce87282e5049789cd05b1d413ba936e322bed

    • SHA512

      c6c44f2f323f379486c3d7b27e0b6e6f766c7a152cd1ca15c702e58a953cb8cddf8a573cf2b9d972087143531d569130e867dbed6738293f38c2692d189151dd

    • SSDEEP

      3072:sr85CDVP6CIqmpRvFLifSC1EKyAqiv/sZpMmZMCNZDgKlGD7rmk:k90RpRvFLiEtTZqmZZNpngXmk

    • Detect Neshta payload

    • Neshta

      Malware from the neshta family is designed to infect itself into other files to spread itself and cause damage.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Modifies system executable filetype association

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

Change Default File Association

1
T1546.001

Privilege Escalation

Event Triggered Execution

1
T1546

Change Default File Association

1
T1546.001

Defense Evasion

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Collection

Data from Local System

1
T1005

Tasks